Zoom Annotation Feature Zero-Click Client Takeover Vulnerability
First seen Aug 12, 2026 · Updated Aug 12, 2026
A flaw in Zoom's screen annotation feature could have allowed any meeting participant to hijack the client of another attendee, including the presenter, without any user interaction. The vulnerability required no click, download, or visible prompt, making it a fully zero-click, in-meeting attack vector. This poses significant risk to organizations relying on Zoom for internal and external communications, including those coordinating distributed teams or automated workflows via meeting integrations.
Technical Analysis
The vulnerability resided in Zoom's real-time annotation subsystem, which processes drawing and typing input overlaid on shared screens during a call. Improper input validation or insufficient sandboxing of annotation data appears to have allowed a malicious participant to craft annotation payloads that executed arbitrary actions on the receiving client, effectively achieving remote code execution or session hijacking without user consent or visible indicators. Because the exploit required no interaction beyond meeting presence, it bypasses standard phishing or social-engineering defenses and evades typical endpoint detection reliant on user-initiated actions. If Zoom clients are used by AI agent orchestration systems (e.g., bots joining meetings for transcription, summarization, or automated note-taking), a compromised client could expose API keys, credentials, or internal network access used by those agents, enabling lateral movement into agent pipelines and connected tool integrations.
Affected Systems
Zoom Desktop and Mobile Clients with screen annotation enabled (specific affected version range not disclosed in source reporting); impacts both presenters and viewing participants during active screen-share sessions with annotation active.
Indicators of Compromise
- No specific IOCs disclosed in source reporting (vulnerability disclosure, not an active exploited campaign at time of publication)
Remediation Steps
- 1
Update Zoom Client
Immediately update to the patched Zoom client version once released by Zoom addressing this annotation flaw.
- 2
Disable Annotation Feature
Until patched, disable the annotation tool organization-wide via Zoom admin settings to eliminate the attack surface.
- 3
Restrict Screen Share and Annotation Permissions
Limit annotation and screen-sharing capabilities to trusted hosts and co-hosts only, reducing exposure to untrusted meeting participants.
- 4
Audit Meeting Bots and Automation Integrations
Review any AI agents, transcription bots, or automated tools that join Zoom meetings to ensure they are isolated from sensitive credentials and cannot be leveraged as a pivot point if compromised.
- 5
Monitor for Anomalous Client Behavior
Deploy endpoint monitoring to detect unusual process spawning or network activity originating from Zoom client processes during meetings.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.